1. Begin with the intended use
Before a production deployment, the parties identify the application, intended users, data categories, model components and operating territory. A conversational assistant, an image-production tool and an automated decision system can present different duties and risks.
We provide infrastructure and agreed engineering services. Depending on the actual activity, a party may also have duties as an AI-system provider, deployer, importer, distributor or general-purpose AI model provider. Contract labels alone do not determine legal roles.
2. European Union AI Act
The EU AI Act can apply to organisations outside the EU when the relevant conditions are met, including certain services placed on the EU market or systems whose outputs are used in the EU. Private hosting or open weights do not create a blanket exemption.
Responsibilities depend on the actor, intended purpose and risk classification. We assess our own role for the agreed service. Customers assess their application and deployment duties, including prohibited practices, appropriate oversight and any applicable high-risk requirements. Each party remains responsible for obligations imposed on it by law.
Implementation dates and supporting guidance can change. Consult the European Commission’s current regulatory-framework guidance and applicable law for the operative requirements, rather than relying on an old timetable or a marketing badge.
3. Transparency and generated content
Applications may need to tell users that they are interacting with AI or that content has been generated or manipulated. Some uses require particular marking, disclosure, provenance or human-review measures. The product integration must implement the duties that apply; a website policy alone is insufficient.
Customers must review generated text, images and video for accuracy, rights and suitability before publishing or relying on them. We do not guarantee factual correctness, uniqueness, non-infringement or fitness for a regulated purpose.
4. Model licensing and documentation
We identify the selected model version and applicable licences as part of deployment scoping. Commercial-use terms, redistribution, adapters and hosted add-on components can have different conditions. An open base model does not imply permission to use every feature of a provider’s hosted system.
Benchmark reports should state the model, hardware, output settings, sample size and methodology. Changes such as quantisation, distillation and reduced sampling steps can affect quality and cannot be assumed to be lossless.
5. Data protection and security
Data protection and AI-system rules address different obligations. A private environment can support control over data paths, but does not by itself establish a lawful basis, satisfy transparency duties or eliminate model risks. Privacy notices, processing contracts, access controls and appropriate assessments remain relevant.
For our handling of website enquiries, read the privacy notice. Customer inference processing is governed by the relevant service and processing agreements.
6. Official guidance and questions
Relevant official resources include the European Commission’s AI regulatory framework, the Commission’s guidance on general-purpose AI models, and the UK ICO’s guidance on AI and data protection. Links to these sources are provided below.
For questions about a proposed deployment, contact hi@eigenvector.app. Provide the use case and territory so the relevant obligations can be discussed in context.
Official resources
European Commission — AI regulatory frameworkEuropean Commission — General-purpose AI guidanceICO — AI and data protectionQuestions about this policy?
Contact EIGENVECTOR LTD at hi@eigenvector.app or through our enquiry form.
Get in touch